Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3458 Vulnerability (CVE-2017-3458)
WordPress Plugin User Profile Picture Information Disclosure (2.4.0)
Liferay Portal CVE-2022-42126 Vulnerability (CVE-2022-42126)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000499)
WordPress Plugin White Label CMS Cross-Site Scripting (1.5.2)